CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

High

CVE-2026-5111

Gravity Forms [gravityforms] < 2.10.1

A security flaw exists in Gravity Forms plugin versions up to 2.10.0, allowing malicious scripts to be injected into WordPress sites via Hi…

High

CVE-2026-5110

Gravity Forms [gravityforms] < 2.10.1

The Gravity Forms plugin for WordPress has a vulnerability in versions up to 2.10.0 that allows an attacker to inject malicious code into a…

High

CVE-2026-5113

Gravity Forms [gravityforms] < 2.10.1

A security flaw exists in Gravity Forms plugin versions up to 2.10.0, which can be exploited by injecting malicious code through hidden inp…

High

CVE-2026-5112

Gravity Forms [gravityforms] < 2.10.1

The Gravity Forms plugin for WordPress contains a security flaw in versions up to 2.10.0, allowing malicious code to be injected into produ…

High

CVE-2026-5109

Gravity Forms [gravityforms] < 2.10.1

The Gravity Forms plugin for WordPress has a vulnerability in versions up to 2.10.0 that allows attackers to inject malicious JavaScript co…

Medium

CVE-2026-6916

Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 3.1.1

The Jeg Kit for Elementor plugin contains a security flaw that allows malicious users with contributor-level access or higher to embed unau…

Medium

CVE-2026-6127

Elementor Website Builder – more than just a page builder [elementor] < 4.0.5

The Elementor Website Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through the _elementor_data meta fie…

Medium

CVE-2024-13362

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.0

The Post SMTP plugin before version 3.1.0 contains a reflected cross-site scripting vulnerability through the url parameter caused by inade…

High

CVE-2026-48838

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.3

The Post SMTP plugin for WordPress, versions 3.6.2 and earlier, is susceptible to stored cross-site scripting (XSS) due to inadequate input…

Critical

CVE-2026-42774

JetEngine [jet-engine] < 3.8.8.2

The JetEngine plugin for WordPress contains a security flaw in versions 3.8.8.1 and earlier, allowing malicious input to bypass normal quer…

High

CVE-2026-40776

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.9

The Eventin plugin for WordPress contains a security flaw that allows unauthorized users to carry out certain actions without proper cleara…

Medium

CVE-2026-4019

Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.6

The Complianz plugin's REST API endpoint is open to unauthorized access due to a flawed permission check in all versions up to 7.4.5. Speci…

Medium

CVE-2026-40795

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1

A security flaw exists in the Amelia plugin for WordPress, affecting versions through 2.2. The issue arises from inadequate permission chec…

CVE

CVE-2026-3220

Speed Optimizer – The All-In-One Performance-Boosting Plugin [sg-cachepress] < 7.7.9

The Autoptimize plugin, Clearfy Cache plugin, and Speed Optimizer plugin are susceptible to unauthenticated Stored Cross-Site Scripting due…

High

CVE-2026-6741

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.2

The LatePoint plugin for WordPress contains a security flaw that allows unauthorized access to certain features. Specifically, versions 5.4…

High

CVE-2026-42384

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.2

The Simply Schedule Appointments Booking Plugin, used with WordPress, contains a security flaw that allows unauthorized access to confident…

Medium

CVE-2025-11762

HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] < 11.3.33

A vulnerability exists in the HubSpot All-In-One Marketing plugin for WordPress, affecting versions up to 11.3.32. This flaw allows authori…

High

CVE-2026-40789

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1

All versions of the Amelia plugin for WordPress prior to version 2.3 contain a security flaw that allows unauthorized individuals to access…

Medium

CVE-2026-25440

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.0

A security flaw exists in the Essential Addons for Elementor plugin, which allows unverified users to execute an illicit operation because …

Medium

CVE-2026-3361

WP Store Locator [wp-store-locator] < 2.3.0

The WP Store Locator plugin for WordPress contains a security flaw that allows malicious users with contributor privileges or higher to emb…

High

CVE-2026-40775

Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.3

The Royal MCP Secure AI Connector plugin for WordPress has a security flaw that allows unverified individuals to bypass standard access con…

Medium

CVE-2026-40773

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.7.10

Authenticated users with subscriber privileges or higher can exploit a security flaw in the rtMedia plugin, allowing them to bypass intende…

High

CVE-2026-39467

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.107.0

The MetaSlider plugin for WordPress contains a flaw that allows authenticated users with editor-level access and above to inject malicious …

Critical

CVE-2026-39465

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.107.0

The MetaSlider plugin for WordPress contains a critical vulnerability that allows malicious users with elevated permissions to inject and r…

High

CVE-2026-39503

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.6

The Easy Digital Downloads plugin for WordPress has a security flaw that allows unauthorized access to certain functions, enabling unauthen…

Medium

CVE-2026-39489

Download Monitor [download-monitor] < 5.1.10

The Download Monitor plugin for WordPress contains a security flaw that allows authorized users with elevated permissions to access and vie…

Medium

CVE-2026-5721

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 6.5.0.5

The wpDataTables plugin for WordPress has a security flaw affecting all versions up to 6.5.0.4, allowing attackers to inject malicious scri…

High

CVE-2026-39472

PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.9.0

A security flaw exists in WordPress plugins up to version 5.9.0 of PDF Invoices & Packing Slips for WooCommerce due to inadequate handling …

High

CVE-2026-6518

CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.17

The Coming Soon & Maintenance Plugin for WordPress is vulnerable to a serious security flaw that allows an authenticated attacker with Admi…

Medium

CVE-2026-2986

Contextual Related Posts [contextual-related-posts] < 4.2.2

The Contextual Related Posts plugin for WordPress contains a security flaw in versions 4.2.1 and earlier, allowing malicious users with con…

Medium

CVE-2026-4160

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.0

The Fluent Forms plugin versions up to 6.1.21 is susceptible to Insecure Direct Object Reference vulnerabilities through the 'submission_id…

High

CVE-2026-5231

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.16.5

The WP Statistics plugin for WordPress has a security flaw that allows attackers to inject malicious code into the plugin's admin pages. Th…

Medium

CVE-2026-3488

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.16.5

The WP Statistics plugin for WordPress contains a flaw in versions up to 14.16.4 that allows unauthorized access to sensitive user informat…

High

CVE-2026-48839

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.16.7

The WP Statistics plugin for WordPress contains a security flaw in versions up to 14.16.6, allowing malicious code injection through unsani…

Medium

CVE-2026-5234

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0

The LatePoint plugin for WordPress has a flaw in its handling of invoices that allows unauthorized access to sensitive financial data. In v…

CVE

CVE-2026-40308

My Calendar – Accessible Event Manager [my-calendar] < 3.7.7

The My Calendar WordPress plugin's AJAX endpoint is vulnerable to parameter injection, allowing an unauthenticated attacker to manipulate t…

Medium

CVE-2025-13364

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.8

The WP Maps plugin contains a security flaw affecting all versions up to 4.8.7. The vulnerability stems from inadequate filtering of user-s…

Medium

CVE-2026-3885

Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.5.0

The Shortcodes Ultimate plugin for WordPress contains a security flaw that allows malicious users with contributor-level permissions or hig…

Medium

CVE-2026-39468

Meta Box [meta-box] < 5.11.2

The Meta Box plugin for WordPress allows authenticated users with at least Contributor permissions up to version 5.11.1 to delete any file …

High

CVE-2026-39463

ManageWP Worker [worker] < 4.9.32

The ManageWP Worker plugin for WordPress is susceptible to stored cross-site scripting (XSS) vulnerabilities up to version 4.9.31, resultin…

High

CVE-2026-39474

Post Duplicator [post-duplicator] < 3.0.11

A vulnerability exists in Post Duplicator for WordPress, affecting versions prior to 3.0.10, where unverified input can be deserialized, al…

Critical

CVE-2026-39492

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.2

The WP Maps plugin for WordPress contains a security flaw in versions 4.9.1 and earlier, allowing malicious code to be injected into databa…

Critical

CVE-2026-39493

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.29

The Simply Schedule Appointments Booking Plugin for WordPress has a security flaw in versions 1.6.9.27 and earlier, allowing malicious user…

Medium

CVE-2025-14732

Elementor Website Builder – more than just a page builder [elementor] < 3.35.6

A vulnerability exists in the Elementor plugin for WordPress, allowing attackers with Contributor-level access or higher to inject maliciou…

Medium

CVE-2026-34903

Ocean Extra [ocean-extra] < 2.5.4

A flaw exists in the Ocean Extra plugin for WordPress, allowing users with Subscriber-level permissions or higher to carry out an illicit o…

CVE

CVE-2025-15611

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 5.5.0

The Popup Box plugin for WordPress had a security flaw prior to version 5.5.0, where it failed to verify authenticity of certain requests b…

Medium

CVE-2026-34897

Media Library Assistant [media-library-assistant] < 3.35

The Media Library Assistant plugin for WordPress contains a security flaw in versions 3.34 and earlier, which allows malicious users with a…

High

CVE-2026-34885

Media Library Assistant [media-library-assistant] < 3.35

The Media Library Assistant plugin for WordPress contains a security flaw in versions 3.34 and earlier, which allows malicious users with a…

Medium

CVE-2025-13368

Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.21

The Xpro Addons plugin for WordPress contains a security weakness in its Pricing Widget's 'onClick Event' setting, which allows malicious u…

Medium

CVE-2025-15064

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.2

The Ultimate Member plugin for WordPress contains a security flaw affecting all versions up to 2.11.1, where user input in the profile desc…

High

CVE-2026-40764

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.0.3

The Contact Form by WPForms plugin, versions 1.10.0.2 and earlier, is susceptible to Cross-Site Request Forgery due to inadequate nonce val…

High

CVE-2026-34886

Simple Membership [simple-membership] < 4.7.2

A flaw exists in the Simple Membership plugin for WordPress, allowing unauthorized users to bypass security checks within certain functions…

Medium

CVE-2026-1710

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 10.6.0

The WooPayments plugin for WooCommerce Payments on WordPress has a security flaw that allows unauthorized changes to its configuration due …

High

CVE-2026-45214

Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.2

The Xpro Elementor Addons plugin for WordPress contains a security flaw in versions 1.5.1 and earlier, which allows malicious users with el…

Medium

CVE-2026-39508

Advanced Coupons for WooCommerce – BOGO Coupons, Store Credit & WooCommerce Coupon Plugin [advanced-coupons-for-woocommerce-free] < 4.7.2

The Advanced Coupons for WooCommerce Coupons plugin contains a security flaw affecting WordPress versions up to 4.7.1.1, allowing malicious…

Medium

CVE-2026-39477

CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.4

The CartFlows plugin for WordPress has a security flaw that allows unauthorized access when the version is 2.2.3 or earlier. Authenticated …

Medium

CVE-2026-42648

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.23

A vulnerability exists in the Spectra plugin for WordPress, affecting versions prior to or equal to 2.19.22. The issue arises from a lack o…

Medium

CVE-2026-39501

FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6

A flaw exists in the FOX plugin for WordPress, where a critical security oversight has been discovered in its authorization mechanism. Spec…

High

CVE-2026-39466

Broken Link Checker [broken-link-checker] < 2.4.8

Authenticated users with at least editor privileges in WordPress installations using Broken Link Checker plugin versions 2.4.7 or earlier a…

High

CVE-2026-39495

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.29

The Simply Schedule Appointments plugin for WordPress contains a security flaw in versions up to 1.6.9.27, allowing malicious users with co…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.